Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Version from cargo and released bin is unsecure! #45

Closed
markus-geiger opened this issue Apr 13, 2020 · 3 comments
Closed

Version from cargo and released bin is unsecure! #45

markus-geiger opened this issue Apr 13, 2020 · 3 comments

Comments

@markus-geiger
Copy link

http://x.x.x.x/%2F is possible! No problem to retrieve ro-files from /etc.

Also would be nyce to see a https-only and an autogenration for self-signed certs.

@notthetup
Copy link

notthetup commented Apr 14, 2020

Indeed! The only latest version published to crates.io seems to be 0.4.7 https://crates.io/crates/simple-http-server

Similarly with releases section of Github. https://github.com/TheWaWaR/simple-http-server/releases

And 0.4.7 doesn't fix #13

@blurayne
Copy link

Version from master states 0.6 and does solve the problem (also when you start with cert it's https).

But this insecurity should be flagged and cargo releases should be updated.

@TheWaWaR
Copy link
Owner

TheWaWaR commented Apr 14, 2020

0.6.0 published. Please update simple-http-server though:

cargo install simple-http-server --force

I only have Linux machine, will upload the binary in release page later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants